The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Google's cloud division is following in thefootsteps of Microsoftwith the launch ofSecurity AI Workbenchthat leverages generative AI models to gain better visi…
Threat actors are employing a previously undocumented "defense evasion tool" dubbed AuKill that's designed to disable endpoint detection and response (EDR) sof…
ceph 16.2.12 GA Security fix for CVE-2022-3650
The Iranian nation-state group known asMuddyWaterhas been observed carrying out destructive attacks on hybrid environments under the guise of a ransomware oper…
Several out of bounds memory access and buffer overflows were fixed in xrdp, an open source project which provides a graphical login to remote machines using M…
The North Korean advanced persistent threat (APT) actor dubbed ScarCruft is using weaponized Microsoft Compiled HTML Help (CHM) files to download additional ma…
As many as 55 zero-day vulnerabilities were exploited in the wild in 2022, with most of the flaws discovered in software from Microsoft, Google, and Apple.Whil…
The ChatGPT-powered Blackmamba malware, which can operate on macOS, Windows, and Linux systems, works as a keylogger, with the ability to send stolen credentia…
The notorious Emotet malware, in itsreturn after a short hiatus, is now being distributed viaMicrosoft OneNote email attachmentsin an attempt to bypass macro-b…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) hasaddeda high-severity flaw affecting the ZK Framework to its Known Exploited Vulnerabilities…
E-commerce industries in South Korea and the U.S. are at the receiving end of an ongoing GuLoader malware campaign, cybersecurity firm Trellix disclosed late l…
E-commerce industries in South Korea and the U.S. are at the receiving end of an ongoing GuLoader malware campaign, cybersecurity firm Trellix disclosed late l…
The Russia-affiliated Sandworm used yet another wiper malware strain dubbedNikoWiperas part of an attack that took place in October 2022 targeting an energy se…
Azure Linux is a public computing platform developed by Microsoft that businesses can use for tasks like app development, analytics, virtual computing, network…
The threat actors behind theKinsingcryptojacking operation have been spotted exploiting misconfigured and exposed PostgreSQL servers to obtain initial access t…
Microsoft's decision to block Visual Basic for Applications (VBA) macros by default for Office files downloaded from the internet has led many threat actors to…
The Vice Society ransomware actors have switched to yet another custom ransomware payload in their recent attacks aimed at a variety of sectors."This ransomwar…
Threat actors affiliated with a ransomware strain known as Play are leveraging a never-before-seen exploit chain that bypasses blocking rules for ProxyNotShell…
A cross-platform botnet, ''MCCrash' that starts out from malicious software downloads on Windows devices and spreads to a range of Linux-based devices was rece…
Red Hat JBoss Web Server 5.7.1 zip release is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, and Microsoft Windows. Red Hat Product …
With 2022 coming to a close, there is no better time to buckle down and prepare to face the security challenges in the year to come. This past year has seen it…
A malicious campaign targeting the Middle East is likely linked toBackdoorDiplomacy, an advanced persistent threat (APT) group with ties to China.The espionage…
The Lazarus Group threat actor has been observed leveraging fake cryptocurrency apps as a lure to deliver a previously undocumented version of the AppleJeus ma…
Several flaws were discovered in jackson-databind, a fast and powerful JSON library for Java. CVE-2020-36518